VDB

CVE-2024-9861

CVE-2024-9861 PUBLISHED CVSS 8.100000381469727 HIGH

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the otp login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they know the phone number associated with that user.

EPSS 0.63% · 48.6th percentile

Risk Scores

CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.63%
48.6th percentile

Affected Products

VendorProductVersions
miniorangeotp_verification_with_firebase0
cyberlord92Miniorange OTP Verification with Firebase*

Timeline

  • Oct 17, 2024 EPSS Score
  • Oct 17, 2024 Coalition ESS Score
  • Oct 17, 2024 CVE Published
  • Oct 18, 2024 Coalition ESS Score
  • Nov 5, 2024 EPSS Score
  • Nov 24, 2024 EPSS Score
  • Dec 21, 2024 Coalition ESS Score
  • Jan 2, 2025 EPSS Score
  • Jan 21, 2025 EPSS Score
  • Jan 28, 2025 Coalition ESS Score
  • Feb 9, 2025 EPSS Score
  • Feb 28, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›